HIPAA Breach News

Employee Terminated for Improperly Dumping PHI

An employee of New Jersey-based BioReference Laboratories has been terminated for failing to follow company protocols – and HIPAA Rules – regarding the secure disposal of documents containing the protected health information of patients.

BioReference Laboratories is the third largest full service clinical diagnostic laboratory in the United States, with locations in New York, New Jersey, Maryland, Massachusetts, Rhode Island, Ohio, Florida, Texas and California. The incident occurred at its facilities in Florida.

Company policies require all sensitive paperwork to be securely shredded prior to disposal, in accordance with HIPAA Rules. However, on March 14, 2017, BioReference Laboratories discovered that documents provided to the employee had been disposed of in a dumpster in Davenport, Florida.

Upon discovery of the incident, BioReference Laboratories launched an investigation and identified the individual responsible. The decision was taken to terminate the employee for the HIPAA breach.

BioReference Laboratories promptly arranged for the documents to be collected and securely destroyed. While PHI was exposed for a short period of time, no evidence was uncovered to suggest any of the documents had been accessed or removed from the dumpster. However, out of an abundance of caution, BioReference Laboratories is providing credit monitoring services to all patients impacted by the incident for a period of 12 months without charge.

The documents contained a range of highly sensitive PHI including patients’ names, addresses, dates of birth, medical record numbers, insurance information, Social Security numbers, diagnosis codes, details of medical tests that had been ordered.

The investigation revealed this was an isolated incident and steps have now been taken to ensure that future HIPAA breaches of this nature do not occur. BioReference Laboratories has taken the decision to update its safeguards and policies and staff will also be reeducated on the importance of securely destroying documents containing protected health information.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 1,772 patients have been affected.

The post Employee Terminated for Improperly Dumping PHI appeared first on HIPAA Journal.

Amedisys Notifies Patients of Improper Disposal Incident

The medical information of certain patients of Amedisys Home Health of Fayetteville, NC has been disposed of improperly, although all information is believed to have been retrieved.

Amedisys ensures all paper copies of patients’ protected health information is shredded and rendered unreadable, indecipherable, and otherwise cannot be reconstructed, in accordance with HIPAA Rules.

However, Baton Rouge, LA-based Amedisys was recently informed that two shredding bins had been found behind a Fayetteville business and had not shredded in accordance with company policies. The bins should have been taken to a recycling center where the documents could be securely shredded.

After being notified of the HIPAA breach, Amedisys arranged for the bins to be retrieved. A full inventory of the documents was then performed to determine whether patients’ protected health information was present in the documents and which patients had PHI exposed. The documents were discovered to contain patients’ names, demographic information and some medical information related to the services provided by Amedisys.

Out of an abundance of caution, all patients impacted by this incident will be offered identity theft protection services, although Amedisys does not believe any of the information in the documents has been accessed by unauthorized individuals other than by the individuals who discovered and reported their find. It also did not appear as if any documents had been removed from the bins, although the possibility cannot be ruled out.

Since the bins were found behind a local business, out of eyesight of the public, it is not believed that anyone other than the individuals who found the documents knew they were there.

An internal investigation is now being conducted by Amedisys to determine how the documents failed to make it to the shredding facility. A review of policies and procedures covering the shredding of sensitive documents is also being conducted. Amedisys will extend that review to the vendor used to collect and shred documents and the subcontractor used to service Amedisys Home Health of Fayetteville.

All patients impacted by the incident are now being notified of the potential privacy violation by mail.

The post Amedisys Notifies Patients of Improper Disposal Incident appeared first on HIPAA Journal.

21 Employees Found to Have Accessed PHI Without Authorization

A routine audit at Virginia Mason Memorial has revealed that employees have been accessing the protected health information of patients without authorization.

Audits of PHI access logs occasionally reveal rogue employees have been improperly accessing the medical records of patients, but what makes this incident stand out is the number of employees that were discovered to have improperly viewed PHI. The audit revealed 21 employees had deliberately accessed PHI without authorization.

Virginia Mason Memorial conducted the audit in January and immediately terminated access to PHI to prevent further privacy breaches. The investigation revealed those 21 employees had accessed the PHI of 419 patients. All of the patients had visited the hospital’s emergency room.

The investigation was conducted internally, although the hospital also brought in a third-party cybersecurity firm to conduct a forensic analysis of its systems. That firm has also been searching the darknet to find out if any of the accessed records have made it onto darknet marketplaces. To date, no patient information appears to have been listed for sale.

A spokesperson for the hospital issued a statement saying, “We believe this to be a case of snooping, or individuals who were bored.” The hospital does not believe the records were accessed with malicious intent.  As a precaution, all affected patients have been offered credit monitoring services without charge.

The employees concerned have been interviewed and disciplined, although for legal reasons, the hospital has not disclosed whether those employees have been terminated for their actions.

The types of information accessed includes demographic information and patients’ medical records. In some instances, it is possible that Social Security numbers were viewed, although financial information was not accessed by any of the employees.

Patients impacted by the breach were notified of the privacy violation last week by mail, according to a report in the Yakima Herald. While it is not clear exactly when in January the privacy violations were discovered, patient breach notifications appear to have been sent outside the 60-day breach notification window of the HIPAA Breach Notification Rule.

In response to the breach, Virginia Mason Memorial has re-educated employees on HIPAA and hospital rules concerning patient privacy and the hospital will now be monitoring access logs more proactively, with “audits going around the clock”.

The incident shows how important it is for healthcare organizations to conduct regular audits of PHI access logs to identify privacy issues before they become a major problem, and the importance of not only providing training on HIPAA Rules and patient privacy, but also regularly reminding employees of the requirements of HIPAA and the penalties for improper PHI access.

The post 21 Employees Found to Have Accessed PHI Without Authorization appeared first on HIPAA Journal.

Protenus Publishes Healthcare Data Breach Report for March 2017

Protenus has released its Breach Barometer report for March 2017, which shows a significant increase in healthcare data breaches and a major jump in the number of individuals who have had their sensitive data exposed or stolen.

In both January and February there were 31 reported healthcare data breaches, although March saw the figure jump to 39 incidents.  February saw relatively few individuals affected by healthcare data breaches. 206,151 patients and health plan members had some of their protected health information exposed last month. However, in March the figure jumped to 1,519,521 – more than 2.5 times the number of individuals impacted by healthcare data breaches in January and February combined. Almost half of those individuals had their ePHI exposed in the same incident – a 697,800-record theft incident reported by Commonwealth Health Corporation.

The Protenus report shows insiders were the biggest cause of the healthcare data breaches reported in March, accounting for 44% of the total. There were 10 insider incidents reported in March that involved insider error and seven were the result of insider wrongdoing.

Hacking incidents made up 28% of the total and resulted in the theft or exposure of 600,270 records. 21% of incidents involved the loss or theft of physical records and devices containing ePHI.  While loss and theft was responsible for the fewest data breaches, those incidents resulted in the exposure of the most records in March, with 737,131 individuals impacted by those incidents. The remaining 8% of breaches could not be categorized as the cause has not been disclosed.

Healthcare providers were the worst hit, registering 84.6% of the incidents. Four incidents were reported by health plans and there was one breach reported by a business associate.

Protenus reports that virtually all data breaches were reported within the 60-day window of the HIPAA Breach Notification Rule. There was a marked improvement in reporting times, taking an average of 45 days from the discovery of the breach to the submission of the breach report to the Department of Health and Human Services’ Office for Civil Rights. In February, the average time from the discovery of the breach to submitting a report to OCR was 478 days. In March, only two covered entities submitted late breach reports – one took 77 days and another took 89 days.

While California is usually the worst affected state, this month Texas gets that honor with 6 reported incidents. Tennessee, Pennsylvania, Kentucky, and Missouri each had three data breaches.

The post Protenus Publishes Healthcare Data Breach Report for March 2017 appeared first on HIPAA Journal.

Ashland Women’s Health Reports Ransomware Attack

Since the start of 2016, cybercriminals have been increasingly turning to ransomware to attack healthcare organizations. Rather than attempting to steal the electronic protected health information of patients, malicious actors are blocking access to ePHI and are issuing ransom demands to restore access.

While large healthcare organizations such as MedStar Health are major targets for cybercriminals, healthcare organizations of all sizes are at risk of experiencing ransomware attacks, even small one-practitioner medical centers.

This week, one such practice has announced a ransomware attack has resulted in patients’ ePHI being encrypted. Ashland Women’s Health (AWH) is a small obstetrics and gynecology practice in Ashland, Kentucky. Earlier this month, AWH submitted a report of a hacking/IT incident to the Department of Health and Human Services’ Office for Civil Rights. The breach report indicates 19,727 patients were impacted.

This week, further information on the security breach has been released. The security breach was caused by a malicious actor who gained access to the computer system used by AWH and installed a ransomware variant called HakunaMatata. HakunaMatata ransomware is a variant of NMoreira ransomware.

While electronic protected health information was encrypted by the ransomware, a ransom payment was not made to regain access to data. AWH was able to recover all encrypted EHR data from backups.

The ransomware attack was reported to the FBI and law enforcement and an investigation is being conducted. AWH has now successfully restored patient data and has brought its systems back online. AWH experienced downtime of around two days following the attack while the infection was removed and data were restored. During that time, medical services continued to be provided, with staff resorting to pen and paper to record health information and schedule appointments.

In accordance with HIPAA Rules, breach notification letters will shortly be sent to all affected patients.

The post Ashland Women’s Health Reports Ransomware Attack appeared first on HIPAA Journal.

Virus Infection at Erie County Medical Center Forces Computer System Shutdown

A computer virus sent via email to staff at Erie County Medical Center in Buffalo, New York – the main teaching hospital used by the University of Buffalo – has forced the hospital to shut down its entire computer system, parts of which remain out of action three days later.

The incident occurred in the early hours of Sunday morning. IT staff reacted promptly and shut down email and took the entire computer system offline as a precaution to prevent the spread of the virus. The IT team, assisted by external security experts, is working to systematically restore its systems. That process is expected to take several days, although most computer systems at the hospital have now been brought back online. The hospital’s email system is still not operational and its website is still inaccessible. The hospital has a backup of all data, including patients’ health information. A full recovery is therefore expected.

Staff at the hospital have been forced to temporarily work with pen and paper while the IT security incident is resolved. Communication between care teams has continued using ECMC’s proprietary text messaging system. A spokesperson for the hospital says operations are continuing as normal and patient services have not been affected.

Peter K. Cutler, ECMC’s Vice President of Communications and External Affairs, said “We have concerns about the motivation that led to this virus, and we are working with the appropriate agencies to determine the validity of whatever information we’ve received as a result of this virus coming into our system.”

The hospital is “confident that no patient information has been compromised,” however, at this stage, that cannot be entirely ruled out. The investigation into the attack is continuing and once systems have been restored, ECMC will be conducting a complete post-infection analysis to ensure that no further malware or viruses remain on its system. Law enforcement agencies, including the FBI, have been notified of the cyberattack.

The nature of the virus has not been disclosed, although the incident bears the hallmarks of a ransomware infection. Targeted ransomware attacks on hospitals are occurring, with at least one malicious actor using Philadelphia ransomware to attack hospitals and encrypt data. Those attacks started in the third week of March.

A decryptor has been released to unlock files encrypted by Philadelphia ransomware, although many ransomware variants have yet to be cracked. Decrypting data is only possible if a ransom is paid, something the FBI and other law enforcement agencies strongly advise against.

In order to ensure a complete recovery from a ransomware attack is possible, healthcare organizations must regularly backup their data and test those backups to make sure data can be recovered in the event of a disaster.

The post Virus Infection at Erie County Medical Center Forces Computer System Shutdown appeared first on HIPAA Journal.

2017 Shaping Up to Be Another Record-Breaking Year for Healthcare Data Breaches

2016 was a particularly bad year for healthcare data breaches. More data breaches were reported than in any other year since the Department of Health and Human Services’ Office for Civil Rights started publishing healthcare data breach summaries in 2009.

In 2016, 329 breaches of more than 500 records were reported to the Office for Civil Rights and 16,655,952 healthcare records were exposed or stolen.

2017 looks set to be another record breaking year for healthcare data breaches. Figures for the first quarter of 2017 show data breaches have increased, with rises in theft incidents, hacks and unauthorized disclosures.

By the end of Q1, 2016, 64 breaches of more than 500 records had been reported to OCR and 3,529,759 had been exposed or stolen.

Between January 1, 2017 and March 31, 2017, OCR received 79 data breach reports from HIPAA covered entities and business associates. Those breaches have resulted in the theft or exposure of 1,713,591 healthcare records.

While fewer individuals have been impacted by healthcare data breaches than in the equivalent period last year, the number of reported breaches has increased by more than 23%.

Hacking incidents have increased by 26%, unauthorized access and disclosures have risen by 28%, and theft incidents have increased by 30%. Incidents involving improper disposal of PHI have remained the same and there has been little change in the number of reported loss incidents.

April has also started poorly, with Ashland Women’s Health having discovered a hacking incident that has resulted in the exposure of 19,727 patient health records.

While hacking incidents have risen year on year, the biggest threat comes from within. Protenus reports that in January, 59.2% of healthcare data breaches were caused by insiders, with February’s healthcare data breach report indicating insiders were responsible for 58% of breaches.

Largest Healthcare Data Breaches in Q1, 2017

 

Organization Covered Entity Type Type of Breach Individuals Affected
Commonwealth Health Corporation Healthcare Provider Theft 697,800
Urology Austin, PLLC Healthcare Provider Hacking/IT Incident 279,663
VisionQuest Eyecare Healthcare Provider Hacking/IT Incident 85,995
Washington University School of Medicine Healthcare Provider Hacking/IT Incident 80,270
Emory Healthcare Healthcare Provider Hacking/IT Incident 79,930
Stephenville Medical & Surgical Clinic Healthcare Provider Unauthorized Access/Disclosure 75,000
Primary Care Specialists, Inc. Healthcare Provider Hacking/IT Incident 65,000
ABCD Pediatrics, P.A. Healthcare Provider Hacking/IT Incident 55,447
WellCare Health Plans, Inc. Health Plan Hacking/IT Incident 24,809
Denton Heart Group Healthcare Provider Theft 21,665

The post 2017 Shaping Up to Be Another Record-Breaking Year for Healthcare Data Breaches appeared first on HIPAA Journal.

3,365 Patients’ Billing Records Potentially Stolen by Hacker

Atlanta-based Skin Cancer Specialists, P.C., has announced a data security incident has been discovered that has resulted in the exposure of the billing records of 3,365 patients.

An unauthorized individual was discovered to have gained access to the healthcare provider’s system on October 15, 2016, with the intrusion detected on February 2, 2017.

The system contained the billing records of 3,365 patients. Those records included patients’ names, addresses, telephone numbers, dates of birth, medical record numbers, physician information and health insurance details. Financial information and Social Security numbers were not viewed or obtained by the attacker.

Skin Cancer Specialists hired a cybersecurity firm to conduct a thorough investigation into the breach to determine how access was gained. Action has now been taken to secure its systems to prevent further cyberattacks.

No evidence of inappropriate use of the billing records was uncovered during the investigation, although patients have been advised to check their explanation of benefits statements for any sign of fraudulent use of their health insurance information. Patients were notified of the breach by mail on April 3, 2017.

Healthcare Hacking Incidents Have Increased by 26% in 2017

2016 was a particularly bad year for healthcare data breaches, with more reported breaches of patient health records than in any other year since the Department of Health and Human Services’ Office for Civil Rights started publishing data breach summaries on its ‘Wall of Shame’.

However, 2017 looks set to be even worse. Healthcare hacking incidents have increased in 2017, with 26% more incidents discovered during the first three months of 2017 than in the corresponding period in 2016.

Up to March 31, 2017, OCR received reports of 24 healthcare hacking/IT incidents, resulting in 811,343 healthcare records being exposed or stolen. 10 of those incidents have been reported in the past 30 days.

The post 3,365 Patients’ Billing Records Potentially Stolen by Hacker appeared first on HIPAA Journal.

Mental Health Histories and Therapy Session Notes of 3,000+ Patients Sold On Darknet

Databreaches.net has discovered a healthcare data breach of more than 3,000 records. Those records appear to have been sold by the hacker responsible for the attack via a darknet marketplace. The records contained health and mental health histories and therapy session notes from 2007 to present.

In total, more than 4,500 patient records were obtained by the hacker, which related to ‘3,000-3,500’ unique individuals. The records included names, addresses, phone numbers and employer details along with SSNs, dates of birth and the names of patients’ physicians.

Worse still, the records contained complete family histories, details of substance abuse, legal histories, health and mental health histories, and detailed ‘complete’ notes of therapy sessions spanning several years.

The individual responsible for stealing the information listed the records for sale on a darknet marketplace advising potential buyers that the records contained “Everything confessed/discussed in complete privacy is in here for thousands of patients.”

The complete set of data was listed for sale for a minimum price of $10,000 and was allegedly sold to one individual. The seller suggested the records could be sold back to the organization from where they were stolen.

It is not clear how the records were stolen, although the seller claims the healthcare organization had ‘not-so-great network security. Databreaches.net was able to identify the source of the data and alerted the organization – Behavioral Health Center in Bangor, Maine. The health center has launched an investigation into the breach and will notify affected patients in due course.

The report of the discovery can be viewed on this link.

The post Mental Health Histories and Therapy Session Notes of 3,000+ Patients Sold On Darknet appeared first on HIPAA Journal.